
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-87165 is a high-severity vulnerability in the Oracle Contract Lifecycle Management for Public Sector product, specifically within the ECC For Award and IDV component of Oracle E-Business Suite. The affected version is V16. Disclosed on September 15, 2026, as part of Oracle's Critical Security Patch Update (CSPU), the vulnerability allows a low-privileged attacker with network access via HTTP to fully compromise the affected application. It carries a CVSS v3.1 base score of 8.8 (High) (Oracle Advisory).
The vulnerability is classified as an easily exploitable flaw (no specific CWE has been publicly disclosed) that can be triggered by a low-privileged, authenticated attacker over HTTP without requiring user interaction. The attack vector is network-based with low attack complexity, meaning no special conditions or race conditions are required for exploitation. Oracle's advisory characterizes the potential outcome as a full takeover of the Oracle Contract Lifecycle Management for Public Sector application, consistent with remote code execution behavior. No public technical write-ups or proof-of-concept code have been identified at this time (Oracle Advisory).
Successful exploitation results in complete compromise of the Oracle Contract Lifecycle Management for Public Sector application, with high impact to confidentiality, integrity, and availability. An attacker could read sensitive procurement and contract data, modify system configurations or application data, and disrupt service availability. Given the public-sector context of the affected product, exploitation could expose sensitive government contracting information and potentially enable lateral movement within connected Oracle E-Business Suite environments (Oracle Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability has an EPSS score of approximately 0.0035 (0.35%), indicating a currently low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection support is available via Qualys scanner (detection ID: 20626) (Oracle Advisory).
Oracle has released a security patch for this vulnerability as part of the September 2026 Critical Security Patch Update, published on September 15, 2026. Organizations running Oracle Contract Lifecycle Management for Public Sector V16 should apply the patch immediately via the Oracle E-Business Suite patch availability documentation. As a temporary measure, Oracle recommends restricting network access to the affected component via HTTP to only authorized users and networks, though this should not be considered a long-term solution. Oracle strongly advises against skipping security patch updates (Oracle Advisory).
Oracle's advisory notes that the company continues to receive reports of attackers exploiting vulnerabilities for which patches have already been released, and strongly urges customers to apply patches without delay. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-87165 has been identified beyond the standard advisory coverage (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."